Ethereal vs. Tcpdump: a comparative study on packet sniffing tools for educational purpose

  • Authors:
  • Felix Fuentes;Dulal C. Kar

  • Affiliations:
  • Texas A&M University-Corpus Christi, Corpus Christi, TX;Texas A&M University-Corpus Christi, Corpus Christi, TX

  • Venue:
  • Journal of Computing Sciences in Colleges
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

There are many free packet-sniffing tools available for download. Ethereal and tcpdump are two of the most popular tools among network administrators. This work compares and contrasts the usefulness and appropriateness of these tools for pedagogical purposes. While ethereal is user-friendlier than tcpdump, tcpdump is less intrusive and hence, can be used in a campus-wide network safer, since it does not readily reveal any data transmitted in a packet. Ethereal can be used in a closed networking lab environment to analyze and study many more protocols. Many class assignments can be designed using these two packet sniffers. Particularly, assignments can be developed to analyze tcpdump's output in real-time for intrusion detection or the understanding of a protocol.